CVE-2025-68943: Medium severity gitea/gitea vulnerability
Published Dec 26, 2025
·Updated
Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.
Affected Software
3 affected componentsFixes available
gitea/gitea<1.21.8
go/code.gitea.io/gitea<1.21.8
1.21.8
Gitea Gitea<1.21.8
Event History
Dec 26, 2025
CVE Published
via MITRE·03:19 AM
Data Sourced
via MITRE·03:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 AM
Data Sourced
via GitHub·06:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68943?
CVE-2025-68943 is considered a medium severity vulnerability due to its potential for user privacy exposure.
2
How do I fix CVE-2025-68943?
To remediate CVE-2025-68943, upgrade to Gitea version 1.21.8 or later.
3
What data is exposed by CVE-2025-68943?
CVE-2025-68943 inadvertently discloses users' login times when sorting by last login time.
4
Which versions of Gitea are affected by CVE-2025-68943?
Gitea versions prior to 1.21.8 are affected by CVE-2025-68943.
5
Is authentication required to exploit CVE-2025-68943?
No, CVE-2025-68943 can be exploited without authentication, making it more dangerous.